Improper Handling of Highly Compressed Data (Data Amplification) Affecting org.asynchttpclient:async-http-client package, versions [,2.16.1)[3.0.0.Beta1,3.0.12)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.63% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGASYNCHTTPCLIENT-19963947
  • published20 Sept 2026
  • disclosed17 Sept 2026
  • credithyperxpro

Introduced: 17 Sep 2026

NewCVE-2026-85721  (opens in a new tab)
CWE-409  (opens in a new tab)

How to fix?

Upgrade org.asynchttpclient:async-http-client to version 2.16.1, 3.0.12 or higher.

Overview

org.asynchttpclient:async-http-client is a maven plugin for the Async Http Client (AHC) classes.

Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) through ChannelManager.newHttpContentDecompressor() in client/src/main/java/org/asynchttpclient/netty/channel/ChannelManager.java. An attacker can exhaust the client's heap and trigger an OutOfMemoryError by sending a small gzip, deflate, or snappy response that inflates without limit during automatic decompression. The vulnerable HTTP/1.1 path uses Netty's HttpContentDecompressor with the no-argument constructor, so a hostile or compromised server, or an attacker who can alter a response in transit, can make the client allocate decompressed data until memory is exhausted.

Workarounds

  • Disable automatic decompression with setEnableAutomaticDecompression(false) and decompress responses manually with your own size limit; this prevents the HTTP/1.1 client from inflating attacker-controlled bodies without bound.
  • On the 2.x line, remove the inflater handler through httpAdditionalChannelInitializer; this prevents the client from installing the unbounded decompressor at all.
  • Run the client behind a proxy that caps response sizes; this limits how much compressed data can reach the client and reduces decompression-bomb impact.

CVSS Base Scores

version 4.0
version 3.1